nancy

Why SBOMs Matter for Industrial and Critical Infrastructure Security

Networking devices, like food, can introduce risks from the big wide world into critical infrastructure systems. Modern industrial systems are a blend of hardware, firmware, and software. As a result, evaluating devices requires more than reviewing a physical Bill of Materials (BOM). You also need the Software BOM (SBOM), which is a formal record containing the details, versions, and supply chain relationships of various software components used in building a product. This information is crucial in vulnerability and asset management, enabling organizations to quickly identify software or component dependencies and supply chain risks.

Growing and persistent threats from hacktivists targeting critical infrastructure

In a joint advisory, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and partners detailed ongoing cyber activity targeting industrial control systems (ICS). To cause disruption and gain publicity, hacktivists often target critical infrastructure, ranging from water treatment facilities to oil well systems. They exploit exposed services, weak authentication, and poor network segmentation in legacy operational technology (OT). Although these hacktivists are generally unsophisticated and mostly cause only temporary loss of view, they show lack of consideration for human safety and incur substantial labor costs associated with operational downtime and network remediation.

Bridging the IT/OT gap for cyber resilience in critical infrastructure

For networking operators in factories, utilities, and government agencies, the convergence of Information Technology (IT) and Operational Technology (OT) is no longer a theoretical concept—it’s reality, and fraught with increasing cybersecurity risks that exploit the gap in between, exposing critical infrastructure to sophisticated threats. Understanding and actively bridging this divide is paramount to maintaining operational resilience and security.

A different bidirectional approach to data diode solutions

Frequently, data diodes have been deployed to create an “air gap” between the Operational Technology (OT) network and the Information Technology (IT) network, protecting critical OT processes from the open risks of IT. Yet, what if your application necessitates two-way communication, the most common network topology? Are data diodes still applicable for securing these systems? YES, through bidirectional data diodes.

Scroll to Top